PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
July 8, 200492 citations

An experience developing an IDS stimulator for the black-box testing of network intrusion detection systems

View Full Paper
DMD. MutzGVGiovanni VignaRKRichard A. Kemmerer

Key Points

Key points are not available for this paper at this time.

Abstract

Signature-based intrusion detection systems use a set of attack descriptions to analyze event streams, looking for evidence of malicious behavior. If the signatures are expressed in a well-defined language, it is possible to analyze the attack signatures and automatically generate events or series of events that conform to the attack descriptions. This approach has been used in tools whose goal is to force intrusion detection systems to generate a large number of detection alerts. The resulting "alert storm" is used to desensitize intrusion detection system administrators and hide attacks in the event stream. We apply a similar technique to perform testing of intrusion detection systems. Signatures from one intrusion detection system are used as input to an event stream generator that produces randomized synthetic events that match the input signatures. The resulting event stream is then fed to a number of different intrusion detection systems and the results are analyzed. This paper presents the general testing approach and describes the first prototype of a tool, called Mucus, that automatically generates network traffic using the signatures of the Snort network-based intrusion detection system. The paper describes preliminary cross-testing experiments with both an open-source and a commercial tool and reports the results. An evasion attack that was discovered as a result of analyzing the test results is also presented.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Mutz et al. (2004) studied this question.

synapsesocial.com/papers/6a10af462eacc880ce643fb2https://doi.org/10.1109/csac.2003.1254342
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection1998 · 656 citations
  2. 2Mining alarm clusters to improve alarm handling efficiency2005 · 154 citations
  3. 3State transition analysis: a rule-based intrusion detection approach1995 · 756 citations
  4. 4Testing and evaluating computer intrusion detection systems1999 · 168 citations
  5. 5Statistical foundations of audit trail analysis for the detection of computer misuse1993 · 122 citations